Key Management for Quantum Communication with Periodic PSK Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum cryptographic communication systems face challenges in reducing operational costs while maintaining communication security, particularly in managing pre-shared keys (PSKs) for key transport without relying on public key infrastructure (PKI) and avoiding the risks associated with continuous use of initial PSK values.

Innovation Solution

A method for automatically updating pre-shared keys (PSKs) during key transport in quantum key distribution networks, integrating this process with encryption key provision protocols to ensure secure communication without the need for PKI, using various timing and synchronization methods for PSK updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If continuous use of initial PSK values is maintained, then operational cost is reduced, but security is compromised due to information leakage risk

Engineering Contradiction:
Improvecommunication securityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements periodic PSK updates at predetermined time intervals during key transport. This periodic action maintains security by preventing long-term use of initial PSK values while reducing operational complexity compared to continuous key management. The system automatically updates PSKs at scheduled intervals without requiring manual intervention or complex reconfiguration.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The key management device automatically performs PSK updates without requiring external intervention or manual configuration. The system self-manages the key rotation process by automatically generating new PSKs, updating them in the communication session, and maintaining security protocols, thereby reducing operational costs while ensuring continuous security.

Inventive Principle:
Principle #25Self-service

2Reliability

If PSK updates are performed frequently, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system incorporates feedback mechanisms where the key management device monitors communication sessions and automatically triggers PSK updates based on predetermined conditions. This feedback-driven approach enables secure key rotation without requiring complex manual management, as the system self-regulates based on session state and security requirements.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs PSK updates in advance based on predetermined time intervals or conditions before potential security threats materialize. This preliminary action ensures security is maintained without requiring reactive complex key management procedures, as updates are scheduled proactively based on security policies rather than responding to complex security events.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4712407A1Key management device, quantum cryptographic communication system, information processing device, key management method, information processing method, and program
Publication Date: 2026.03.18 KK TOSHIBA
  • EP4712407A1 patent drawingFigure 1
  • EP4712407A1 patent drawingFigure 2
  • EP4712407A1 patent drawingFigure 3~4

AI summary

According to one arrangement, a key management device is connected to a first application by a wired communication scheme or a wireless communication scheme. The key management device includes a processing unit implemented by at least one processing device and configured to transmit a response including an application key and PSK information indicating a pre-shared key (PSK) used to establish a first communication session between the first application and the key management device to the first application, when receiving a request for the application key used to encrypt or decrypt communication in the first application.